Critical Infrastructure Under Siege as Warlock Ransomware Continues SharePoint Exploitation
A sophisticated hacking group linked to China has been exploiting vulnerabilities in Microsoft’s popular collaboration platform, SharePoint, to launch devastating ransomware attacks against critical infrastructure, government, and education entities. The Warlock ransomware gang, believed to be operated by the Longlegs and Storm-2603 groups, has been using zero-day exploits to gain initial access to vulnerable systems, often weeks before public disclosure of the flaws.
Symantec researchers have been tracking the group’s activities for months, and their findings paint a concerning picture. Warlock attackers favor exploiting SharePoint bugs, including recent vulnerabilities such as CVE-2026-32201 and CVE-2026-45659. The group’s arsenal also includes the infamous ToolShell exploit, which was discovered in 2025 to have compromised over 400 SharePoint servers worldwide.
The scope of the attacks is staggering, with at least four victim organizations hit in Portuguese- and Spanish-speaking countries over the past two months. These include critical infrastructure operators, a water utility, a telecommunications provider, a regional government body, and a university. In one particularly brazen attack, the hackers deployed a tool to disable security software on 40 systems before executing Warlock ransomware on at least 33 of them.
The exploitation of SharePoint flaws is typically followed by a series of malicious activities, including webshell deployment, ASP.NET machine key exfiltration, and the deployment of a forced signed payload for remote code execution (RCE). The group relies on DLL sideloading for in-memory code execution and drops additional payloads from legitimate file-sharing and storage services. They also use living-off-the-land tools for reconnaissance and command execution.
One notable tactic employed by Warlock attackers is the abuse of Visual Studio Code’s built-in tunnel feature to establish covert remote network access. This allows them to blend into traffic that typically originates from developer or administrator workstations, making it difficult for security teams to detect their activities.
To mitigate these attacks, organizations must take immediate action. This includes patching and updating SharePoint deployments as soon as possible, implementing robust intrusion detection systems, and conducting regular vulnerability assessments. Additionally, administrators should be vigilant in monitoring system logs for suspicious activity and implement robust backup and recovery procedures to minimize the impact of a ransomware attack.
The continued exploitation of ToolShell and other related SharePoint vulnerabilities by Warlock attackers serves as a stark reminder that organizations must prioritize cybersecurity above all else. By staying informed and proactive, security teams can help prevent these devastating attacks from occurring in the first place.
Source: SecurityWeek — 2026-10-02